Am I talking to a human or a bot? Is that face on Zoom a real person or gen-AI trained to sound like my boss? Is the software update I allowed coming from the vendor or from an adversary installing malware? Should this user be able to see that content? How much can I trust they are who they say they are?
On Thursday, September 24, 2026, the Internet Governance Project (IGP) will host Identity Online: Shaping Governance Through Digital Identifiers, a workshop at the Washington College of Law, American University, in Washington, D.C. where we’ll unpack the governance challenges of online identification to better understand what’s at stake.
Register for in-person attendance here.
The program
Four sessions, plus a closing synthesis:
- Sessions will include:
1. Identifiers and Governance: An analytical framework with Milton Mueller & Brenden Kuerbis from Georgia Tech and Ryan Galluzzo from NIST2. PKI and the Governance of Trust on the Web with Johannes Sedlmeir from Uni. of Münster, Cecilia Testart from Georgia Tech, and Karl Grindal from Uni. of New Hampshire3. Identifiers and Content Control: Age Verification and Content Provenance with Harry Oppenheimer from Georgia Tech, Ilia Murtazashvili from Uni of Pittsburgh (TBC) and Paul Lekas from the Global Public Policy and Government Affairs, Software & Information Industry Association
4. Organizational Identity, Payments and Digital Money with Jeremy Grant from the Better Identity Coalition, Johannes Sedlmeir, Uni of Münster, Karla McKenna from GLEIF, Karim Farhat and Vagisha Srivastava from Georgia Tech
The workshop runs as a pre-conference tutorial on Day 0 of TPRC54. Attendance is in person, registration is free, and seating is limited. Register here.
For registration to the remaining 2 day conference at TPRC use this link: https://www.tprcweb.com/registration
Identity is not the same thing as an identifier
Identity is an ontological claim: there is a thing in the world, a person, a machine, a company, or a shipping container, that is distinct from everything else. Identifiers are sets of abstract symbols or tokens that humans create to differentiate among real-world entities for purposes of governance or management. Digital identifiers are therefore always part of an information system that relies on organizational structures and human operation as well as machines to serve a function of communication and control.
Debates about “digital identity” have tended to drift toward privacy and selfhood, while the operative decisions (who issues the tokens, on what evidence, recorded in whose registry, validated against whose root of trust) are made somewhere else and largely out of view. That is why our focus will be on the political economy of identity system governance, and the interactions of government and private sector actors as they navigate tough policy choices in a rapidly changing identity ecosystem.
Identifiers are everywhere, and they do three things
Utilities number telephone poles. Mobile operators assign 15-digit International Mobile Equipment Identity (IMEI) numbers to handsets and International Mobile Subscriber Identity (IMSI) numbers to subscriber accounts. The Internet has IP addresses, postal systems have regional codes, ad networks have cookies. Governments issue passports, taxpayer numbers, and drivers’ licenses; universities and employers issue ID cards; every online service issues user IDs and authenticates them one way or the other.
Once such a system is in place, it enables three governance functions. Exclusion: identifiers allow an administrator to gatekeep access to information, resources, and physical space. Operational awareness: they make the behavior of identified entities (machines as much as people) visible to whoever runs the system. Accountability: they let a manager assign responsibility and track what was done, to whom it was done, and under what conditions.
That’s why conflicts over identifier systems are rarely just technical. The workshop will open by putting an analytical model on the table, and then spend the day running it over live cases to learn based on what fits the model and what doesn’t. We hope to see you there!
Wish I could be there, but I’m really glad to see this being treated as a governance question rather than simply a technical one. What makes the political economy of digital identity so urgent, in my view, is the growing struggle over who gets to define, verify and enforce identity online: Age verification is a good example: once platforms and private identity providers become the gatekeepers deciding what counts as sufficient proof of age, they are not simply implementing regulation they are extensively helping define how regulation works in practice, and who gets access to what… The same is true of content provenance: when dominant platforms and technology providers control the infrastructures through which authenticity is established, they can shape what users, regulators, and even civil-society actors are able to recognize as “trusted” information.
This creates a deeper institutional problem. Companies that control identity infrastructures can increasingly become “de facto” intermediaries between citizens, civil society and the state, while lawmakers often end up regulating infrastructures and standards that are already privately designed and deployed. With AI accelerating synthetic identities and impersonation, the question is who gets to decide what counts as a valid identity and who has the power to make that decision consequential. Really looking forward to seeing where this research goes.